HIPAA compliance software: a HIPAA software platform for Security Rule safeguards
If your product touches PHI, HIPAA applies the day your first BAA is signed. Complies tracks the administrative, physical, and technical safeguards as owned obligations, not a binder.
Last updated August 2026
HIPAA compliance software tracks the safeguards the law requires around protected health information: Complies maps the Security Rule's administrative, physical, and technical safeguards to your actual controls, keeps business associate agreements signed and current, and collects the evidence that proves the safeguards operate. HIPAA is three rules working together: the Privacy Rule governs how PHI is used and disclosed, the Security Rule (164.308, 164.310, 164.312) demands documented safeguards for electronic PHI starting with a risk analysis, and the Breach Notification Rule requires notifying affected individuals, and HHS, when unsecured PHI is breached. For a healthtech startup, that means signed BAAs with every vendor touching PHI, access controls and audit logging on systems holding it, encryption, workforce training, and written policies. Complies turns each safeguard into an obligation with an owner and a due date, pulls technical evidence from AWS, Okta, and Google Workspace, and drafts policy starting points your team approves. There is no official HIPAA certification, which makes a defensible, documented posture the real goal. HIPAA safeguards overlap heavily with SOC 2 and ISO 27001, so work done there pre-fills your HIPAA map, and Growth at $199 a month includes the cross-mapping.
Complies handles it with policy management software and compliance evidence collection, with every control cross-mapped to the other frameworks you run. For the tooling side of it, compare what compliance software actually costs.
What HIPAA asks of you, in plain language
| Code | What it demands | How Complies helps |
|---|---|---|
| 164.308(a)(1) | Conduct and document a risk analysis covering all ePHI | The risk register generates the risk analysis HHS asks for first in any investigation: threats, likelihood, impact, and treatment, each with an owner and a review date. |
| 164.312(a) | Control technical access to systems that hold ePHI | Maps SSO, IAM, and unique user IDs to the access control standard, schedules access reviews, and flags shared or orphaned accounts on PHI systems. |
| 164.312(b) | Record and examine activity in systems containing ePHI | Collects audit logging configuration and log review evidence from AWS on a schedule, so the audit controls standard proves itself continuously. |
| 164.308(b) | Hold business associate agreements with every vendor touching PHI | Tracks which vendors receive PHI, stores each signed BAA as evidence with a renewal date, and flags new integrations that lack one. |
| 164.404 | Notify affected individuals of breaches of unsecured PHI | Keeps the breach response plan, notification templates, and HHS reporting steps approved in advance, and logs incident timelines as evidence of the process. |
Collect once, comply many times
The Security Rule is mostly the same engineering work the other frameworks ask for: 164.312(a) access control matches SOC 2 CC6.1, ISO 27001 A.5.15, and GDPR Art. 32; the 164.308(a)(1) risk analysis matches SOC 2 CC3.2 and ISO Clause 6.1.2; audit logging matches PCI DSS Req. 10. What HIPAA adds is PHI-specific: BAAs, minimum necessary use, and breach notification to individuals and HHS. Complies maps shared controls once, marks them satisfied across frameworks, and isolates the genuinely HIPAA-only work, so a SOC 2-ready healthtech team sees most of its HIPAA map pre-filled.
| Control area | HIPAA | Also satisfies |
|---|---|---|
| Access control | 164.312(a) | SOC 2 CC6.1 · ISO A.5.15 · GDPR Art. 32 · PCI Req. 7 |
| Risk analysis | 164.308(a)(1) | SOC 2 CC3.2 · ISO Clause 6.1.2 · PCI Req. 12.3 |
| Audit logging | 164.312(b) | SOC 2 CC7.2 · ISO A.8.15 · PCI Req. 10 |
| Vendor agreements | 164.308(b) | SOC 2 CC9.2 · ISO A.5.19 · GDPR Art. 28 |
See the full crosswalk on the control mapping software page.
HIPAA compliance software compared, and what each vendor actually publishes
Most HIPAA compliance software falls into two camps: healthcare specialists built around the risk assessment, training, and BAA workflow, and multi-framework GRC platforms that treat HIPAA as one mapping among many. The split that matters more to a buyer is whether the vendor will tell you the price. Every figure below was read off the vendor's own pricing page on August 11, 2026, or is labeled as a third-party benchmark.
| Platform | How it handles HIPAA | Pricing published? | Best fit |
|---|---|---|---|
| Complies | Security Rule safeguards under 164.308, 164.310, and 164.312 tracked as owned obligations, cross-mapped to SOC 2, ISO 27001, GDPR, and PCI DSS. | Yes. Starter $79, Growth $199, Scale $499 per month billed yearly. Self-serve signup. | US companies of 5 to 200 people that need HIPAA next to SOC 2 or ISO 27001 without a sales cycle. |
| Accountable | HIPAA specialist: security risk assessment, BAA management, training, policies, data inventory, vendor tracking. | Yes. Basic $169, Plus $254, Pro $679 per month billed annually ($199, $299, $799 monthly). Extra seats $9 to $19. | Business associates and smaller healthcare orgs that want HIPAA only, priced on the page. |
| Compliancy Group | HIPAA specialist with OSHA and SOC 2 programs, live coaching sessions, policy manuals, training, risk assessment. | Yes. Foundation from $99 and Growth from $249 per month billed annually for 1 to 10 employees, plus $8 to $10 per employee. | Medical practices and clinics that want guided support rather than a self-serve tool. |
| Vanta | HIPAA is one of 35 plus frameworks, applied largely as a mapping over a SOC 2 style control set. | No. Quote only. Vendr median $20,000 a year, range $7,500 to $57,236, n=372, re-verified August 2026. | Funded startups already buying SOC 2 automation that want HIPAA folded in. |
| Drata | Multi-framework GRC with HIPAA available, plus third-party risk bundled into its GRC Foundation tier. | No. Quote only. Vendr median $24,868 a year. | Growth-stage tech companies running several frameworks with a dedicated compliance owner. |
| Secureframe | Multi-framework, HIPAA offered alongside SOC 2 and ISO 27001. | Partly. Fundamentals from $7,000 a year, then quoted. Vendr median $20,000 a year. | Teams that want managed onboarding and a named customer success contact. |
| Sprinto | Multi-framework automation with HIPAA in its framework list. | No. Quote only. Vendr median $15,000 a year. | Small engineering teams doing SOC 2 first and HIPAA afterwards. |
The Vendr figures are third-party medians from buyers who negotiated those contracts, not vendor list prices, and they move. We publish them because the four quote-only vendors publish nothing at all. Directory sites list other numbers for several of these products with no methodology attached, so we leave those out. If a figure here goes stale, the vendor's own page wins: check it before you sign.
Six things HIPAA compliance software has to get right
A risk analysis that survives scrutiny
The risk analysis at 164.308(a)(1)(ii)(A) is the single most cited failure in OCR enforcement, and OCR runs a Risk Analysis Initiative built around it. Complies keeps threats, likelihood, impact, treatment, owner, and review date in one register you can export.
BAAs tracked as live obligations
A business associate agreement is not a filing task. Complies records which vendors touch PHI, stores each signed BAA with a renewal date, and flags a new integration that went live without one.
Evidence pulled on a schedule
Access reviews, log checks, encryption settings, and training completion get collected from AWS, Okta, and Google Workspace on a recurring cadence, so the safeguards prove they operate rather than just existing on paper.
One control library, several frameworks
Access control, logging, risk analysis, and incident response are shared with SOC 2, ISO 27001, and PCI DSS. Complies satisfies a shared control once and marks it across every framework, so HIPAA work is not done twice.
Policies your team can approve
Complies drafts the Security Rule policy set as a starting point, then routes it for human approval and attestation. Nobody ships a policy the company has not read and agreed to.
Honest about what nobody can sell you
There is no official HIPAA certification, so any HIPAA certified badge is marketing. What software can deliver is a documented, defensible posture, and that is what the readiness score and export pack are for.
Getting HIPAA ready with Complies
Map where PHI lives and connect your stack
Connect AWS, Okta, and Google Workspace, mark which systems store or transmit ePHI, and let Complies build the safeguard map across 164.308, 164.310, and 164.312.
Run the risk analysis and close the gaps
Work the risk register into the documented risk analysis HHS expects, sign missing BAAs, and approve the AI-drafted policies and training obligations Complies assigns to owners.
Keep safeguards evidenced, not just written
Access reviews, log checks, training refreshers, and BAA renewals land on the calendar with owners. The readiness score shows your defensible posture, and the export pack backs it up.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
HIPAA questions, answered
HIPAA compliance software tracks the safeguards the HIPAA Security Rule requires around electronic protected health information and keeps the evidence that they operate. In practice that means a documented risk analysis, administrative, physical, and technical safeguards mapped to real controls, signed business associate agreements, workforce training, written policies, and an incident response plan. No tool makes you compliant on its own, and none of them can certify you.
It depends on whether the vendor will tell you. Complies runs $79 to $499 a month. HIPAA specialists that publish rates sit in a similar band: Accountable from $169 a month billed annually, Compliancy Group from $99 a month plus a per-employee charge, both read from their own pricing pages in August 2026. Of the multi-framework platforms, Secureframe publishes a floor of $7,000 a year for its single-framework Fundamentals package, while Vanta, Drata and Sprinto publish nothing; third-party medians collected by Vendr in February 2026 put those contracts at roughly $15,000 to $25,000 a year. Audit and assessment work is billed separately by whoever does it.
No, because there is nothing to certify against. HHS runs no HIPAA certification program and accredits no certifying body, so a HIPAA certified badge is a vendor claim rather than a regulatory status. What software can produce is a defensible record: a current risk analysis, tracked safeguards, evidence that they operate, and signed BAAs. That is what a hospital security review and an OCR investigation both ask to see.
Yes, and it is required rather than addressable. 45 CFR 164.308(a)(1)(ii)(A) tells you to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information", and the very next specification requires you to act on what you find. It is the failure OCR cites most often, and the agency has been running a Risk Analysis Initiative built around it since late 2024. HHS also publishes a free Security Risk Assessment Tool aimed at small and medium providers.
Yes, and it is the cheaper path. The Security Rule and the SOC 2 common criteria ask for largely the same engineering: 164.312(a) access control lines up with CC6.1, the 164.308(a)(1) risk analysis with CC3.2, and 164.312(b) audit controls with CC7.2. A platform that cross-maps satisfies a shared control once and marks it in both frameworks, leaving only the PHI-specific work: BAAs, minimum necessary use, and breach notification. Complies includes every framework cross-mapped from Growth at $199 a month.
It depends on what else you are being asked for. If enterprise buyers want SOC 2 as well as HIPAA, choose a platform that cross-maps, because roughly the same controls satisfy both and a HIPAA-only tool will leave you buying twice. If you are a practice or a clinic with no SOC 2 pressure, a HIPAA specialist such as Accountable or Compliancy Group will feel more prescriptive and includes coaching. Weigh published pricing heavily at this size: a quote-only vendor usually means a sales cycle and an annual contract.
Not yet. HHS published a notice of proposed rulemaking, RIN 0945-AA22, in the Federal Register on January 6, 2025, and the comment period closed on March 7, 2025. As of August 2026 no final rule has been published, so the existing Security Rule is still the one you are measured against. The proposal would tighten several current requirements, including making encryption and multi-factor authentication mandatory rather than addressable and adding asset inventory and network mapping duties. Build against today's rule, and keep an eye on the docket.
No, and neither does anyone else: HHS offers no official HIPAA certification, so any badge claiming it is marketing. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee regulatory outcomes. Your auditor and regulators decide; Complies gets you ready, with a documented risk analysis, tracked safeguards, and evidence that they operate.
Almost certainly not; you are most likely a business associate, a vendor that creates, receives, or maintains PHI for a covered entity. That still puts the Security Rule and Breach Notification Rule on you directly, and every hospital deal will require a signed BAA. Complies tracks your obligations as a business associate, including the BAAs you in turn need from your own subcontractors.
Encryption is an addressable specification, not optional but risk-driven: you implement it where reasonable and appropriate, or document why an alternative works. In practice, encrypting ePHI in transit and at rest is the expected answer for a cloud product, and it also makes breached data "secured", which changes your notification duties. Complies collects your encryption settings from AWS as recurring evidence.
Very well. Access control, audit logging, risk analysis, and incident response are shared between the Security Rule and SOC 2 CC-series criteria, so controls you built for SOC 2 pre-fill the HIPAA map in Complies. What remains is PHI-specific: BAAs, minimum necessary policies, training, and breach notification. Healthtech buyers commonly ask for both, and one control library serves both audits.
HIPAA Security Risk Assessment: How to Do One
SRABest HIPAA Risk Assessment Tools for Practices and Healthtech
HEALTHCAREHealthcare Compliance Software: Best Tools for Providers
CROSSWALKControl Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS
Start your HIPAA readiness today
Growth includes every framework, cross-mapped, at $199 a month.